마이크로칩 8월
This page was machine-translated and may differ from the original. View original

Symantec warns of Dragonfly attacks targeting the energy sector.

Google 우선 소스Published2017.09.08 15:21
Dragonfly uses Shelter, an evasion framework, to develop applications loaded with Trojans.

Symantec has warned of a renewed surge in attacks targeting the energy industry by the cyber espionage group Dragonfly.

A new type of cyberattack targeting the energy industry in Europe and North America is potentially devastating. The group behind these attacks is known as Dragonfly. Active since at least 2011, the Dragonfly attack group was revealed in 2014 and then went quiet for a while before resurfacing in the past two years. The second wave of Dragonfly attacks appears to have begun in late 2015, employing the same tactics and methods employed in the initial attacks.

According to Symantec's research, so-called "Dragonfly 2.0" attacks have seen a marked increase this year. Symantec has observed strong indications of Dragonfly activity targeting companies in the US, Turkey, and Switzerland, as well as evidence of activity targeting companies in other countries. While the US and Turkey were also targeted during the initial Dragonfly attacks, the latest attacks reveal a significant increase in attacks targeting Turkish companies.

The Dragonfly 2.0 attack, similar to the initial attack, uses various attack methods to gain access to the victim's network, including ▲malicious emails ▲watering hole attacks ▲Trojan horse-loaded software. The first attack detected by Symantec in the resurfaced Dragonfly campaign was a December 2015 attack where malicious emails disguised as year-end party invitations were sent to targets in the energy sector.

They also used watering hole attacks to infect websites likely visited by industry workers, stealing network credentials. These stolen credentials were then used in subsequent attacks, including installing backdoors against targeted organizations. In attacks conducted in 2016 and 2017, the Dragonfly group leveraged the evasion framework Shellter to develop applications loaded with Trojans. Symantec has also observed the Dragonfly group compromising legitimate software to deliver malware to victims.

The "energy industry," targeted by the Dragonfly Group, has seen increased interest from cyber attackers over the past two years. The most notable cyberattack, the 2015-2016 Ukrainian power outage, was caused by a cyberattack, resulting in a blackout affecting hundreds of thousands of residents. More recently, there have been reports of attempted attacks on power grids in some European countries and hacking of companies managing nuclear power plants in the United States. The Dragonfly Group appears to be interested in learning how energy facilities operate and accessing the operating systems themselves, raising the possibility of sabotaging or controlling these systems.

The original Dragonfly campaign appears to have been nothing more than a "discovery phase," where the attackers simply sought to gain access to the networks of targeted organizations. However, given the potential for more destructive objectives in recent campaigns, including access to operating systems, this suggests a new phase of attack is likely.

The most notable aspect of the recently confirmed Dragonfly attack is the attackers' use of screen capture. Attackers have been observed displaying screen capture files using easily identifiable formats, such as [device description and location] and [organization name]. The string "cntrl" used in many device descriptions appears to indicate that the devices have access to the operating system.

Yoon Gwang-taek, CTO of Symantec Korea, said, “The Dragonfly attack group has been targeting energy companies’ networks using complex attack methods, and the level of their attacks suggests that they may not stop there but may even develop into cyber sabotage.” He urged, “Domestic companies should also always update their software to the latest version and apply security patches to avoid being harmed.”
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
김지혜 기자